U.S. and international cybersecurity authorities this week released additional guidance to help health care and other critical infrastructure leaders defend their networks from Volt Typhoon, a People’s Republic of China state-sponsored group that has been pre-positioning itself on U.S. networks to disrupt critical services in the event of increased geopolitical tensions or conflict with the U.S. and its allies. 

“This bulletin is as much for CEOs as it is for CIOs and CISOs,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “In this alert, the federal government clearly warns us that the Chinese government, through its cyber proxies, is preparing to disrupt the U.S. critical infrastructure we all depend upon, should military conflict erupt with the U.S. and our allies. Health care leaders may want to evaluate and empower development of robust contingency plans for business and clinical continuity should external energy, water, transportation or communications systems be disrupted. Understanding cyber risk as enterprise risk and global strategic risk will help individual organizations prepare for highly disruptive cyberattacks, including those that target mission-critical third parties. Dynamic third-party risk management programs and at least annual cyber table-top exercises are strongly recommended in this heightened cyber threat environment." 

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency Oct. 15 released an emergency directive advising federal agencies to take stock of their F5 BIG-IP…
Headline
In part one of a new blog, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk,…
Perspective
Public
This week, the FBI issued an urgent warning to all users — including hospitals — of a critical security soft spot within Oracle’s E-Business Suite, stating “…
Headline
The Health Sector Coordinating Council Oct. 7 released its Sector Mapping and Risk Toolkit, created to help health care providers and other organizations…
AHA Cyber Intel
As of Oct. 3, 2025, 364 hacking incidents had been reported to the U.S. Department of Health and Human Services Office for Civil Rights, affecting over 33…
Headline
The AHA Oct. 6 released a Cybersecurity Advisory urging immediate action against a critical Oracle E-Business Suite vulnerability that is remotely exploitable…